Elevation of Privilege Vulnerability in Windows Kernel-Mode Drivers
CVE-2026-40408

7.8HIGH

What is CVE-2026-40408?

The vulnerability in Windows Kernel-Mode Drivers presents a serious risk by allowing an authorized attacker to execute a use after free exploit. This could potentially enable the attacker to elevate their privileges locally, leading to unauthorized access to critical system functions. Users and administrators are urged to apply patches and take necessary security measures to mitigate this risk.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9140

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8755

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7291

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.